Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Uncontrolled Search Path Element in Qt Network OpenSSL TLS backend allows rogue CA certificate loading
Vulnerability Description
An Uncontrolled Search Path Element vulnerability in the OpenSSL TLS backend of Qt Network (qtbase) in Qt Qt Framework (Unix) allows a local attacker to load a rogue CA certificate as a trusted system authority via a crafted certificate file placed in the application's working directory.
CVSS Information
CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
对搜索路径元素未加控制
Vulnerability Title
Qt 代码问题漏洞
Vulnerability Description
Qt是Qt开源的一个跨平台的应用程序开发框架。 Qt存在代码问题漏洞,该漏洞源于OpenSSL TLS后端的未控制搜索路径元素问题,允许本地攻击者通过将特制证书文件放置在应用程序工作目录中加载恶意CA证书作为受信任的系统权威。
CVSS Information
N/A
Vulnerability Type
N/A